Skip to content

Commit 9ee905f

Browse files
vars
1 parent 8845da6 commit 9ee905f

File tree

2 files changed

+12
-10
lines changed

2 files changed

+12
-10
lines changed

src/content/docs/magic-network-monitoring/rules/static-threshold.mdx

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,8 @@ import { Render } from "~/components";
1313
params={{
1414
productName: "Magic Network Monitoring",
1515
autoAdvertiseURL: "/magic-network-monitoring/rules/#rule-auto-advertisement",
16-
ruleIpPrefixesURL: "/magic-network-monitoring/rules/#rule-ip-prefixes"
16+
ruleIpPrefixesURL: "/magic-network-monitoring/rules/#rule-ip-prefixes",
17+
rulesURL: "/magic-network-monitoring/rules/"
1718
}}
1819

1920
/>

src/content/partials/networking-services/mnm/rules/static-threshold.mdx

Lines changed: 10 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,7 @@ params:
33
- productName
44
- autoAdvertiseURL
55
- ruleIpPrefixesURL
6+
- rulesURL
67
---
78

89
import { DashButton } from "~/components";
@@ -29,13 +30,13 @@ You can visit the [API documentation](/api/resources/magic_network_monitoring/su
2930

3031
## Recommended rule configuration
3132

32-
You can create [Magic Network Monitoring rules](/magic-network-monitoring/rules/) to monitor the traffic volume of your network for a set of IP prefixes and / or IP addresses. The traffic volume threshold for these rules is also set by you. If the traffic volume threshold is crossed, Magic Network Monitoring will send an alert via email, webhook, or PagerDuty.
33+
You can create <a href={props.rulesURL}>{props.productName} rules</a> to monitor the traffic volume of your network for a set of IP prefixes and / or IP addresses. The traffic volume threshold for these rules is also set by you. If the traffic volume threshold is crossed, {props.productName} will send an alert via email, webhook, or PagerDuty.
3334

34-
Follow the guidelines outlined in this page to create appropriate Magic Network Monitoring rules and set accurate rule thresholds.
35+
Follow the guidelines outlined in this page to create appropriate {props.productName} rules and set accurate rule thresholds.
3536

3637
### Rule IP prefixes
3738

38-
Cloudflare recommends that customers start by creating one Magic Network Monitoring rule for each public `/24` IP prefix within their network. It is helpful to include the range of the `/24` IP prefix to make it easier to find and filter for the rule in Magic Network Monitoring analytics.
39+
Cloudflare recommends that customers start by creating one {props.productName} rule for each public `/24` IP prefix within their network. It is helpful to include the range of the `/24` IP prefix to make it easier to find and filter for the rule in {props.productName} analytics.
3940

4041
As you become more familiar with the traffic patterns across each IP prefix, we encourage you to create more complex rules with IP prefixes that are smaller or larger than a `/24` prefix depending on your needs. You can also combine and monitor multiple IP prefixes within the same rule.
4142

@@ -45,9 +46,9 @@ Follow the steps below to configure appropriate rule thresholds.
4546

4647
#### Initial rule configuration
4748

48-
When you initially configure Magic Network Monitoring, you may not know the typical traffic volume patterns across each of your IP prefixes. Cloudflare recommends that you set a high rule threshold of either 10 Gbps (gigabits per second) or 10 Mpps (million packets per second) that is unlikely to be crossed during initial configuration.
49+
When you initially configure {props.productName}, you may not know the typical traffic volume patterns across each of your IP prefixes. Cloudflare recommends that you set a high rule threshold of either 10 Gbps (gigabits per second) or 10 Mpps (million packets per second) that is unlikely to be crossed during initial configuration.
4950

50-
This will allow you to collect initial information about the typical traffic volume for a Magic Network Monitoring rule without receiving any alerts. After you have collected and analyzed the historical traffic data for an Magic Network Monitoring rule, the threshold should be adjusted to an appropriate value.
51+
This will allow you to collect initial information about the typical traffic volume for a {props.productName} rule without receiving any alerts. After you have collected and analyzed the historical traffic data for an {props.productName} rule, the threshold should be adjusted to an appropriate value.
5152

5253
| Threshold type | Recommended rule threshold to collect initial data |
5354
| :---- | :---- |
@@ -58,7 +59,7 @@ This will allow you to collect initial information about the typical traffic vol
5859

5960
After creating the initial set of rules to monitor your network traffic, you should collect 14-30 days of historical traffic volume data for each rule.
6061

61-
Cloudflare recommends that new customers set a rule threshold that is two times larger than the maximum non-attack traffic observed for a one minute time interval within an Magic Network Monitoring rule.
62+
Cloudflare recommends that new customers set a rule threshold that is two times larger than the maximum non-attack traffic observed for a one minute time interval within an {props.productName} rule.
6263

6364
To find the maximum non-attack traffic for a one minute time interval over the past 14-30 days, you can filter for the specific rule you want to analyze. To do that:
6465

@@ -73,16 +74,16 @@ To find the maximum non-attack traffic for a one minute time interval over the p
7374
| :---- | :---- | :---- |
7475
| _Monitoring Rule_ | _equals_ | `<RULE_NAME>` |
7576

76-
Once the rule filter is selected in Magic Network Monitoring Analytics, you can check the historical traffic volume data for the rule over the selected time period. We recommend that you check your historical traffic volume data in increments of seven days since that is the largest window that shows one hour time intervals. You can select a custom seven-day time range in Magic Network Monitoring Analytics by going to the top right corner of Magic Network Monitoring analytics, opening the time window dropdown, and selecting **Custom range**.
77+
Once the rule filter is selected in {props.productName} Analytics, you can check the historical traffic volume data for the rule over the selected time period. We recommend that you check your historical traffic volume data in increments of seven days since that is the largest window that shows one hour time intervals. You can select a custom seven-day time range in {props.productName} Analytics by going to the top right corner of {props.productName} analytics, opening the time window dropdown, and selecting **Custom range**.
7778

7879
You should review the selected seven-day time range and identify the largest traffic volume peak. Then, click and drag on the largest traffic peak to view the traffic volume data for a smaller time window. Continue until you are viewing the traffic volume data in one-minute intervals.
7980

80-
Record the largest traffic volume peak for the rule in a spreadsheet, then repeat this process across 14-30 days of data. The rule threshold should be updated to be two times the largest traffic spike for a one minute time interval across 14-30 days of data. You should go through this process to set the threshold for each Magic Network Monitoring rule.
81+
Record the largest traffic volume peak for the rule in a spreadsheet, then repeat this process across 14-30 days of data. The rule threshold should be updated to be two times the largest traffic spike for a one minute time interval across 14-30 days of data. You should go through this process to set the threshold for each {props.productName} rule.
8182

8283
### Rule duration
8384

8485
Your IP prefixes may experience inconsistent spikes in traffic volume across one minute time intervals. We recommend that you set a rule duration of 120 seconds or greater to reduce false positive alerts on short-term non-malicious traffic spikes. A rule duration of 120 seconds means that the traffic volume must be above the rule threshold for 120 seconds before an alert is fired.
8586

8687
### Adjusting rules over time
8788

88-
After you update your first set of rule thresholds based on historical traffic data, it will be important to monitor for Magic Network Monitoring alerts to check if the rule thresholds are appropriate. Customers are encouraged to adjust the rule thresholds and the duration over time to find the ideal alert sensitivity level for their specific network environment.
89+
After you update your first set of rule thresholds based on historical traffic data, it will be important to monitor for {props.productName} alerts to check if the rule thresholds are appropriate. Customers are encouraged to adjust the rule thresholds and the duration over time to find the ideal alert sensitivity level for their specific network environment.

0 commit comments

Comments
 (0)